Threat mitigation system and method

US12407716B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12407716-B2
Application numberUS-202418585687-A
CountryUS
Kind codeB2
Filing dateFeb 23, 2024
Priority dateFeb 23, 2023
Publication dateSep 2, 2025
Grant dateSep 2, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A threat mitigation platform includes: an agent subsystem configured to generate an initial notification concerning a security event within a computing platform; a generative AI-based planner subsystem configured to receive the initial notification and generate a mitigation plan to address, in whole or in part, the security event within the computing platform; an executor subsystem configured to iteratively process the mitigation plan using a generative AI model to generate an output; and an output formatter subsystem configured to format the output and generate a summarized human-readable report for the initial notification.

First claim

Opening claim text (preview).

What is claimed is: 1. A threat mitigation platform comprising: an agent subsystem, comprising at least one processor coupled with a memory device, including one or more agents executed on one or more security-relevant subsystems, wherein the one or more agents are configured to generate an initial notification concerning a security event within a computing platform; a generative AI-based planner subsystem including a plurality of generative AI models, wherein one or more of the plurality of generative AI models are configured to receive the initial notification and generate a mitigation plan to address, in whole or in part, the security event within the computing platform, including selecting a generative AI model from the plurality of generative AI models within a model repository based upon, at least in part, operation requirements; an executor subsystem including the selected generative AI model, wherein the selected generative AI model is configured to iteratively process the mitigation plan to generate an output, wherein the selected generative AI model is further configured to utilize one or more tools to process the mitigation plan, wherein the one or more tools include: a decompression tool to decompress a compressed initial notification; and an identification tool to identify an owner of a domain associated with the initial notification; and an output formatter subsystem including a large language model, wherein the large language model is configured to format the output and generate a summarized human-readable report for the initial notification. 2. The threat mitigation platform of claim 1 wherein the generative AI-based planner subsystem is configured to utilize one or more tools to process the initial notification. 3. The threat mitigation platform of claim 2 wherein the one or more tools includes one or more of: a decoding tool to decode an encoded initial notification; a decompression tool to decompress a compressed initial notification; and an identification tool to identify an owner of a domain associated with the initial notification. 4. The threat mitigation platform of claim 1 wherein the one or more tools includes: a decoding tool to decode an encoded initial notification. 5. The threat mitigation platform of claim 1 wherein the executor subsystem is configured to utilize several loops and/or nested loops to generate the output. 6. The threat mitigation platform of claim 1 wherein the output formatter subsystem is configured to utilize a formatting script to generate the summarized human-readable report for the initial notification. 7. The threat mitigation platform of claim 1 wherein the summarized human-readable report defines recommended next steps and/or disclaimers. 8. A threat mitigation platform comprising: an agent subsystem, comprising at least one processor coupled with a memory device, including one or more agents executed on one or more security-relevant subsystems, wherein the one or more agents are configured to generate an initial notification concerning a security event within a computing platform; a generative AI-based planner subsystem including a plurality of generative AI models, wherein one or more of the plurality of generative AI models are configured to receive the initial notification and generate a mitigation plan to address, in whole or in part, the security event within the computing platform, including selecting a generative AI model from the plurality of generative AI models within a model repository based upon, at least in part, operation requirements; an executor subsystem including the selected generative AI model, wherein the selected generative AI model is configured to iteratively process the mitigation plan to generate an output, wherein the selected generative AI model is further configured to utilize one or more tools to process the mitigation plan, wherein the one or more tools include: a decompression tool to decompress a compressed initial notification; and an identification tool to identify an owner of a domain associated with the initial notification; and an output formatter subsystem including a large language model, wherein the large language model is configured to format the output and generate a summarized human-readable report for the initial notification, wherein the summarized human-readable report defines recommended next steps and/or disclaimers. 9. The threat mitigation platform of claim 8 wherein the generative AI-based planner subsystem is configured to utilize one or more tools to process the initial notification. 10. The threat mitigation platform of claim 9 wherein the one or more tools includes: a decoding tool to decode an encoded initial notification; a decompression tool to decompress a compressed initial notification; and an identification tool to identify an owner of a domain associated with the initial notification. 11. The threat mitigation platform of claim 8 wherein the one or more tools includes: a decoding tool to decode an encoded initial notification. 12. The threat mitigation platform of claim 8 wherein the executor subsystem is configured to utilize several loops and/or nested loops to generate the output. 13. The threat mitigation platform of claim 8 wherein the output formatter subsystem is configured to utilize a formatting script to generate the summarized human-readable report for the initial notification. 14. A threat mitigation platform comprising: an agent subsystem, comprising at least one processor coupled with a memory device, including one or more agents executed on one or more security-relevant subsystems, wherein the one or more agents are configured to generate an initial notification concerning a security event within a computing platform; a generative AI-based planner subsystem including a plurality of generative AI models, wherein one or more of the plurality of generative AI models are configured to receive the initial notification and generate a mitigation plan to address, in whole or in part, the security event within the computing platform, including selecting a generative AI model from the plurality of generative AI models within a model repository based upon, at least in part, operation requirements; an executor subsystem including the selected generative AI model, wherein the selected generative AI model is configured to iteratively process the mitigation plan to generate an output, wherein the selected generative AI model is further configured to utilize one or more tools to process the mitigation plan, wherein the one or more tools include: a decompression tool to decompress a compressed initial notification; and an identification tool to identify an owner of a domain associated with the initial notification; and an output formatter subsystem including a large language model, wherein the large language model is configured to format the output and generate a summarized human-readable report for the initial notification, wherein: the output formatter subsystem is configured to utilize a formatting script to generate the summarized human-readable report for the initial notification, and the summarized human-readable report defines recommended next steps and/or disclaimers. 15. The threat mitigation platform of claim 14 wherein the generative AI-based planner subsystem is configured to utilize one or more tools to process the initial notification. 16. The threat mitigation platform of claim 15 wherein the one or more tools includes one or more of: a decoding tool to decode an encoded initial notification; a decompression tool to

Assignees

Inventors

Classifications

  • using machine learning or artificial intelligence · CPC title

  • Natural language generation · CPC title

  • Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities · CPC title

  • G06N3/0475Primary

    Generative networks · CPC title

  • Test or assess a computer or a system · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12407716B2 cover?
A threat mitigation platform includes: an agent subsystem configured to generate an initial notification concerning a security event within a computing platform; a generative AI-based planner subsystem configured to receive the initial notification and generate a mitigation plan to address, in whole or in part, the security event within the computing platform; an executor subsystem configured t…
Who is the assignee on this patent?
Reliaquest Holdings Llc
What technology area does this patent fall under?
Primary CPC classification G06N3/0475. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Sep 02 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).